Daily Threat Intelligence Report

This report contains following information

  1. Overall statistics
    1. Number of domains detected
    2. Number of domains detected by Google Safe Browsing
    3. IP address behind entry-level domains
    4. date of collection
  2. Top 10 domain statistics
    1. count (number of redirection paths that contain this domain)
    2. tier (1 is entry-level domain, 2 is intermediate hop, 3 is final landing domain)
    3. registar
    4. organization
  3. Top 10 IP statistics
    1. count
    2. location (city, country, region)
    3. hostname
    4. organization
  4. Consolidated redirection path
    1. green: tier one domain
    2. yellow: tier two domain
    3. red: tier three domain
num_domainnum_linksnum_full_urlnum_safebrowsing_maliciousnum_vt_maliciousdateipuser_agent
04144361463302020-10-26103.224.182.207Android
tierdomaincountregistrarname_serversorg
0tier_1puracandelatv.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
1tier_1secondnaturecd.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
2tier_103calls.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
3tier_1ddiziizle.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
4tier_1ribbon-art.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
5tier_1benstreaming.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
6tier_1ecatomb.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
7tier_1a-doctor-in-the-house.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
8tier_1ptidico.com1GoDaddy.com, LLCNS1.ABOVE.COMNone
9tier_1okuloncesiegitimi.net1GoDaddy.com, LLCNS1.ABOVE.COMNone
10tier_2bidr.trellian.com193ABOVE.COM PTY LTD.NS1.TRELLIAN.COMREDACTED FOR PRIVACY
11tier_2us.redirectbuzz.club108Gandi SASns-2.awsdns-00.comPPCBUZZ
12tier_2trkads.info81DANESCO TRADING LTDNS1.DIGITALOCEAN.COMDANESCO TRADING LTD.
13tier_2google.com81MarkMonitor, Inc.NS1.GOOGLE.COMGoogle LLC
14tier_20redira.com57ABOVE.COM PTY LTD.NS1.ABOVE.COMREDACTED FOR PRIVACY
15tier_2recode.pw32Gandi SASNS-1611.AWSDNS-09.CO.UKNone
16tier_2amobil.online22Gandi SASNS-1714.AWSDNS-22.CO.UKNone
17tier_2technoblogs.net21GANDI SASNS-1196.AWSDNS-21.ORGPPCBUZZ
18tier_2robocrafthq.com15GANDI SASNS-115.AWSDNS-14.COMPPCBUZZ
19tier_2link.searchemoji.global15GoDaddy.com, LLCNS03.DOMAINCONTROL.COMNone
20tier_3google.com_LOOP_181NoneNoneNone
21tier_3clk.news-headlines.co30NoneNoneNone
22tier_3carsnspeed.net26GANDI SASNS-1120.AWSDNS-12.ORGPPCBUZZ
23tier_3pes20.proasdf.com20GoDaddy.com, LLCNS61.DOMAINCONTROL.COMDomains By Proxy, LLC
24tier_3amobil.online8NoneNoneNone
25tier_3samsung.com8NoneNoneNone
26tier_3brainberries.co8GoDaddy.com, LLCchuck.ns.cloudflare.comBedigital Corporation
27tier_3top.newshub.co.uk6OVH [Tag = OVH-FR]pNone
28tier_3amazon.com5MarkMonitor, Inc.NS1.P31.DYNECT.NETAmazon Technologies, Inc.
29tier_3blog.sfgate.com5CSC CORPORATE DOMAINS, INC.NS1.HEARSTNP.COMHearst Communications, Inc.
iphostnamecityregionorgpostalcountry_nametiercount
0103.224.182.207lb-182-207.above.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_1261
1100.37.135.2pool-100-37-135-2.nycmny.fios.verizon.netNew York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_385
2103.224.182.206bidr.trellian.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_2193
3165.22.162.145nanSanta ClaraCaliforniaAS14061 DigitalOcean, LLC95051United Statestier_281
4103.224.212.241lb-212-241.above.comCaulfield SouthVictoriaAS133618 Trellian Pty. Limited3193Australiatier_257
5209.132.243.15nanWyomingMichiganAS7296 Alchemy Communications, Inc.49509United Statestier_226
6204.44.79.214204.44.79.214.static.quadranet.comLos AngelesCaliforniaAS8100 QuadraNet Enterprises LLC90014United Statestier_219
7172.217.12.132lga34s19-in-f4.1e100.netWestburyNew YorkAS15169 Google LLC11590United Statestier_216
8130.211.115.44.115.211.130.bc.googleusercontent.comCouncil BluffsIowaAS15169 Google LLC51502United Statestier_214
966.232.112.8466-232-112-84.static.hvvc.usTampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_214
1066.232.112.8566-232-112-85.static.hvvc.usTampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_214
1166.232.112.7566-232-112-75.static.hvvc.usDenverColoradoAS29802 HIVELOCITY, Inc.80210United Statestier_214
12100.37.135.2pool-100-37-135-2.nycmny.fios.verizon.netNew York CityNew YorkAS701 MCI Communications Services, Inc. d/b/a Verizon Business10004United Statestier_385
13162.243.10.151nanNew York CityNew YorkAS14061 DigitalOcean, LLC10011United Statestier_322
1454.172.16.98ec2-54-172-16-98.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_39
1552.45.50.0ec2-52-45-50-0.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_39
1652.203.50.59ec2-52-203-50-59.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_37
17158.177.130.8454.82.b19e.ip4.static.sl-reverse.comLas VegasNevadaAS36351 SoftLayer Technologies Inc.89111United Statestier_36
1835.174.102.54ec2-35-174-102-54.compute-1.amazonaws.comVirginia BeachVirginiaAS14618 Amazon.com, Inc.23471United Statestier_35
1966.232.112.6866-232-112-68.static.hvvc.usTampaFloridaAS29802 HIVELOCITY, Inc.33606United Statestier_35
20151.101.0.200nanSingaporeSingaporeAS54113 Fastly048508Singaporetier_35
2123.221.210.196a23-221-210-196.deploy.static.akamaitechnologies.comNewarkNew JerseyAS16625 Akamai Technologies, Inc.07175United Statestier_35

Have other ideas? / Want to subscribe to get threat intelligence report? / Contact

Zhouhan Chen, NYU Center for Data Science, zc1245@nyu.edu, Personal Website